PE-6 Physical Protection

Monitoring Physical Access

Medium Risk Moderate Medium Cost

PE-6 requires monitoring physical access to the facility where the system resides to detect and respond to physical security incidents, and reviewing physical access logs periodically and upon occurrence of potential physical incidents. For healthcare this covers data centers, server closets, EHR workstation areas with restricted access, HIM vaults, and other spaces protecting systems or media with ePHI.

Control Objective

Detect unauthorized or anomalous physical access to facilities and controlled areas supporting ePHI systems through ongoing monitoring and timely log review.

Implementation Guidance

  1. Identify in-scope areas: data centers, IDF/MDF closets, badge-controlled clinics areas, HIM archives, and backup media rooms.
  2. Implement monitoring appropriate to risk: badge readers with logs, visitor systems, guards, and/or CCTV with retention.
  3. Define review frequency for physical access logs (e.g., weekly for data center; after every door-forced alarm).
  4. Alert on anomalous events: after-hours access, door held/forced, repeated denied badges, tailgating reports.
  5. Respond per incident procedures — investigate, revoke access if needed, coordinate with IR when systems may be affected.
  6. Retain logs and video per policy to support investigations and audits.
  7. Include contracted security operations with documented review evidence.
  8. Correlate physical events with logical access anomalies when investigating suspected insider or break-in scenarios.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

After-hours data center badge

Alert fires for an unexpected 2 a.m. entry; PE-6 review confirms a sanctioned vendor window — or escalates if unmatched to tickets.

Forced-door alarm on HIM vault

Security responds, video is retained, and access lists are revalidated; privacy is notified because ePHI records may have been exposed.

Weekly badge log review

Compliance samples data-center access logs, finds a terminated contractor badge still working, and triggers PE-2/PS-4 correction.

Best Practices

  • Risk-based monitoring coverage.
  • Real-time alerts for high-impact doors.
  • Scheduled log reviews with sign-off.
  • Retain video/logs for investigation windows.
  • Tie physical incidents to IR when systems at risk.
  • Review after every anomalous event, not only on calendar.

Common Gaps & Violations

  • Cameras installed but never reviewed.
  • Badge logs exist with no periodic review.
  • Alarms ignored as 'nuisance'.
  • No retention — footage overwritten before investigation.
  • Server closet access completely unlogged.

Required Documentation

  • Physical access monitoring procedure
  • In-scope area inventory
  • Alert/response playbooks
  • Periodic log review evidence
  • Retention settings for logs/video

How to Test & Validate

  1. Confirm monitoring coverage on in-scope areas.
  2. Review recent alert tickets and response times.
  3. Sample periodic log review sign-offs.
  4. Verify retention meets policy.
  5. Trace one physical anomaly to investigation notes.

Audit Considerations

Facility access controls without monitoring are incomplete. Assessors ask for badge log reviews, camera coverage of sensitive rooms, and incident response to physical events.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(a) Facility Access Controls — limit physical access to electronic information systems while ensuring authorized access.
  • 164.310(a)(2)(iii) Access Control and Validation — procedures to control and validate access to facilities.
  • 164.308(a)(6) Security Incident Procedures — physical security incidents may be security incidents requiring response.
  • 164.312(b) Audit Controls — physical access logs complement electronic audit trails for investigations.

Compliance Tips

  • Put weekly data-center badge review on a named owner's calendar with screenshots saved.
  • Ensure forced-door and after-hours alerts page someone 24x7.
  • After terminations, include physical access monitoring checks in the offboarding sample.

Frequently Asked Questions

Do all clinics need CCTV for PE-6?

Monitoring must be appropriate to risk — badge logs and reviews may suffice for some areas; higher-risk rooms often warrant cameras or guards.

How does PE-6 relate to PE-3?

PE-3 enforces physical access control; PE-6 monitors and reviews that access for anomalies and incidents.

How often must logs be reviewed?

Define frequency by area risk and also review upon potential incidents — document both.

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-6
  • HIPAA § 164.310(a)
  • Related controls: PE-2, PE-3, PE-8, IR-4, AU-6

Need Help Implementing PE-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.